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Probabilistic ada p ti ve dir e ct optimis m control in Time Warp 
Alois Ferscha 

July 1995 ACM SIGSIM Simulation Digest , Proceedings of the ninth workshop on 

Parallel and distributed simulation PADS '95, volume 25 issue l 
Publisher: IEEE Computer Society, ACM Press 

Full text available: ^ ^ ^ (|| Additional Information: full citation , abstract , references , citings , index 
Publisher Site terms 

In a distributed memory environment the communication overhead of Time Warp as 
induced by the rollback procedure due to "overoptimistic" progression of the simulation is 
the dominating performance factor. To limit optimism to an extent that can be justified 
from the inherent model parallelism, an optimism control mechanism is proposed, which 
by maintaining a history record of virtual time differences from the time stamps carried by 
arriving messages, and forecasting the timestam ... 

Keywords: CM-5, PVM, Petri nets, RS6000 cluster, Time Warp, forecast models, 
optimism control 
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Why goo d e ngin eers ( somet i mes ) c reate bad interfac es Q 
Donald R. Gentner, Jonathan Grudin 

March 1990 Proceedings of the SIGCHI conference on Human factors in computing 

systems: Empowering people CHI '90 
Publisher: ACM Press 

Full text available* fP| pdf(829 19 KB). Additional Information: ful l cit ati on, abstract, r eferences , citings, index 

This paper presents a view of system design that shows how good engineering practice 
can lead to poor user interfaces. From the engineer's perspective, the ideal interface 
reflects the underlying mechanism and affords direct access to the control points of the 
mechanism. The designer of the user interface is often also the designer of the 
mechanism (or at least is very familiar with the mechanism), and thus has a strong bias 
toward basing the interface on the engineering model. The user, ho ... 

Shock resistant Time Warp Q 
Alois Ferscha, James Johnson 

May 1999 Proceedings of the thirteenth workshop on Parallel and distributed 
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simulation PADS "99 

Publisher: IEEE Computer Society 

Full text available: g_pMt^iJ@J<B) Additional Information: full citation , abstract , references , citings, index 
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In an attempt to cope with time-varying workload, traditional adaptive Time Warp 
protocols are designed to react in response to performance changes by altering control 
parameter configurations, like the amount of available memory, the size of the 
checkpointing interval, the frequency of GVT computation, fossil collection invocations, 
etc.\ We call those schemes x ' reactive" because all control decisions are undertaken 
based on historical performance information collected at runtime, and come int ... 

4 Applications in logistics, transportation, and distribution: Advanced aviation concep ts Q 
via simulation ; re sear ch flig ht s i mulation of future auto nomous aircraft operations 

Mario S. V. Valenti Clari, Rob C. J. Ruigrok, Bart W. M. Heesbeen, Jaap Groeneweg 
December 2002 Proceedings of the 34th conference on Winter simulation: exploring 

new frontiers WSC 02 
Publisher: Winter Simulation Conference 

Full text available: |£| pdf(60 4.2 8 KB ) Additional Information: fu ll citatio n, abstract, references 

A key element in the development and innovation of future aviation concepts and systems 
is research flight simulation. Research flight simulation is applied when the performance 
and perception of human pilots is a key measure of the overall assessment. This paper 
will give an overview of the research simulation set-up of the National Aerospace 
Laboratory (NLR), Amsterdam, the Netherlands, which is used for the human-in-the-loop 
evaluation of future operational concepts. Special attention is g ... 

5 Incentives to help stop floods Q 
Clifford Kahn 

February 2001 Proceedings of the 2000 workshop on New security paradigms NSPW 
'00 

Publisher: ACM Press 

Full text available: 1g|pd f(588 1 3 K B) Additional Information: full citation, references, index terms 



6 Managing ti m e for service and security 
Ruth Nelson, Elizabeth Schwartz 

September 1996 Proceedings of the 1996 workshop on New security paradigms NSPW 
'96 

Publisher: ACM Press 

Full text available: ||| pdf(380 02 KB) Additional Information: full citation, ind e x ter m s 
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Intellige nt information dissemination ser vi ces i n hybrid sat ell i te-w ir e l ess n etworks 
Eddie C. Shek, Son K. Dao, Yongguang Zhang, Darrel J. Van Buer, Giovanni Giuffrida 
December 2000 Mobile Networks and Applications, volume 5 issue 4 
Publisher: Kluwer Academic Publishers 

Full text available- ff\ pdf(527 68 KB) Ac,c, ' t ' ona, Information: full c i tatio n, ab st ract, re fere n ces, citings, ind ex 
' ™ '"' terms 

The need for rapid deployment and user mobility suggest the use of a hybrid 
satellite&dash;wireless network infrastructure for important situation awareness and 
emergency response applications. An Intelligent Information Dissemination Service 
&lpar;IIDS&rpar; has been developed to support the dissemination and maintenance of 
extended situation awareness throughout such a network information infrastructure in a 
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seamless manner. One of the goals of IIDS is to transparently handle the mismatches ... 

8 Illustrative risks to the public in the u s e of computer systems and related tech no l o gy Q 
Peter G. Neumann 

January 1996 ACM SIGSOFT Software Engineering Notes, volume 21 issue 1 
Publisher: ACM Press 

Full text available: pdf(2 .54 MB) Additional Information: full citation 



9 Improving Network Operations With Intelligent Agents Q 
Nathan J. Muller 

July 1997 International Journal of Network Management volume 1 issue 3 
Publisher: John Wiley & Sons, Inc. 

Full text available: |g| pdf(314.75 KB) Additional Information: full citation, abstract, i nde x terms 

Automating network and system management tasks has never been easier, since the 
advent of intelligent agents. This article describes the uses and advantages of intelligent 
agents, to identify and resolve problems locally, instead of dispatching technicians to 
remote locations, which is both expensive and time&hyphen consuming. © 1997 John 
Wiley & Sons, Ltd. 



Illustrative risks to the public in the use of computer systems and related technology Q 
Peter G. Neumann 

January 1992 ACM SIGSOFT Software Engineering Notes, Volume 17 issue 1 
Publisher: ACM Press 

Full text available: ^ pdf(1.65 MB) Additional Information: full citation, citings, index terms 



11 A TCP tuning daemon 

Tom Dunigan, Matt Mathis, Brian Tierney 

November 2002 Proceedings of the 2002 ACM/IEEE conference on Supercomputing 

Supercomputing '02 
Publisher: IEEE Computer Society Press 

Full text available- f55 pdf(1 55 23 KB) Add ' t ' onal Information: full citation, abstract, references, citings, index 
™ terms 

Many high performance distributed applications require high network throughput but are 
able to achieve only a small fraction of the available bandwidth. A common cause of this 
problem is improperly tuned network settings. Tuning techniques, such as setting the 
correct TCP buffers and using parallel streams, are well known in the networking 
community, but outside the networking community they are infrequently applied. In this 
paper, we describe a tuning daemon that uses TCP instrumentation data f ... 

Keywords: TCP, autotuning, data grids, high-performance networking 



12 Spatio-temporal correlations and rollback distributions in o ptimistic simulations 
B. J. Overeinder, A. Schoneveld, P. M. A. Sloot 

May 2001 Proceedings of the fifteenth workshop on Parallel and distributed 
simulation PADS '01 

Publisher: IEEE Computer Society 
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In this paper we study the influence of spatio-temporal correlations on the dynamic 
runtime behavior of the optimistic parallel Time Warp simulation method. By using the 
Ising spin model, we show experimentally that the distribution of the number of rolled 
back events behaves as a power-law distribution over a large range of sub-critical Ising 
temperatures and decays exponentially for super-critical Ising temperatures. For critical 
Ising temperatures, where long-range correlations occur, t ... 

Kerne l s : Ve rtig o : a utomatic performance-setting for Linux Q 
^ Krisztian Flautner, Trevor Mudge 
V December 2002 ACM SIGOPS Operating Systems Review, volume 36 issue si 
Publisher: ACM Press 

Full text available- f^l pdf(2 01 MB) Additional Information: full citation , abstract , references , cited by , index 
■ [Aj _ . -:. terms 

Combining high performance with low power consumption is becoming one of the primary 
objectives of processor designs. Instead of relying just on sleep mode for conserving 
power, an increasing number of processors take advantage of the fact that reducing the 
clock frequency and corresponding operating voltage of the CPU can yield quadratic 
decrease in energy use. However, performance reduction can only be beneficial if it is 
done transparently, without causing the software to miss its deadlines. ... 

14 Digital si mu lation as an evaluation aid in t he d ev el opment of dyn am i c color graphics Q 
human-machine interfaces 

James R. Delaney 

March 1982 Proceedings of the 15th annual symposium on Simulation ANSS '82 
Publisher: IEEE Computer Society Press 

Full text available: ^ pdf(1.32 M B ) Additional Information: full citation, abstr act, i ndex te r ms 

As part of a continuing effort in the area of system control of military communications 
networks, the MITRE Corporation, under the auspices of the Rome Air Development 
Center, has developed a testbed for the evaluation of graphics human-machine interfaces 
for communications network control centers. The testbed uses a MITRE-developed 
communications network simulator, SCAT/G, to drive the candidate network status 
displays. By duplicating the dynamics of the communications network and its envi ... 

15 C o ntr olling high ba n dwi dt h aggregate s in the network I I 
Ratul Mahajan, Steven M. Bellovin, Sally Floyd, John Ioannidis, Vern Paxson, Scott Shenker 
July 2002 ACM SIGCOMM Computer Communication Review, volume 32 issue 3 

Publisher: ACM Press 

Full text available 1^1 pdf(299.37 KB) Additional Information: full citation, abs tract , refe r e n ces , citings, index 

te r ms 

The current Internet infrastructure has very few built-in protection mechanisms, and is 
therefore vulnerable to attacks and failures. In particular, recent events have illustrated 
the Internet's vulnerability to both denial of service (DoS) attacks and flash crowds in 
which one or more links in the network (or servers at the edge of the network) become 
severely congested. In both DoS attacks and flash crowds the congestion is due neither to 
a single flow, nor to a general increase in traffic, bu ... 

16 Session 7: Saving energy with just in time instruct io n delivery I I 
^ Tejas Karkhanis, James E. Smith, Pradip Bose 

>^ August 2002 Proceedings of the 2002 international symposium on Low power 
electronics and design ISLPED '02 
Publisher: ACM Press 

Full text available - fl!| pdf(225 32 KB) Adc, ' t ' onal Information: full c i tat ion, a bstract , references , citings, i ndex 

terms 
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Just-In-Time instruction delivery is a general method for saving energy in a 
microprocessor by dynamically limiting the number of in-flight instructions. The goal is to 
save energy by 1) fetching valid instructions no sooner than necessary, avoiding cycles 
stalled in the pipeline — especially the issue queue, and 2) reducing the number of 
fetches and subsequent processing of mis-speculated instructions. A simple algorithm 
monitors performance and adjusts the maximum number of in-flight instruct ... 

Keywords: adaptive processor, instruction delivery, low-power 



1 7 Papers: An analysis o f usin g reflec t ors fo r distributed denial-of-service attacks I I 
Vern Paxson 

N/ July 2001 ACM SIGCOMM Computer Communication Review, volume 3i issue 3 
Publisher: ACM Press 

Full text available: gpdf(1.02 MB ) Additional Information: f ul l citati o n, abstract, references, citings 

Attackers can render distributed denial-of-service attacks more difficult to defend against 
by bouncing their flooding traffic off of reflectors; that is, by spoofing requests from the 
victim to a large set of Internet servers that will in turn send their combined replies to the 
victim. The resulting dilution of locality in the flooding stream complicates the victim's 
abilities both to isolate the attack traffic in order to block it, and to use traceback 
techniques for locating the source ... 

18 Risks to the public Q 
^ P. G. Neumann 

N/ October 1987 ACM SIGSOFT Software Engineering Notes, volume 12 issue 4 
Publisher: ACM Press 

Full text available: ^ pdf(1.60 MB ) Additional Information: full citation, index term s 



19 What packets may come: automata for network monitoring I I 
A. Karthikeyan Bhargavan, Satish Chandra, Peter J. McCann, Carl A. Gunter 

>^ January 2001 ACM SIGPLAN Notices , Proceedings of the 28th ACM SIGPLAN-SIGACT 

symposium on Principles of programming languages POPL '01, volume 36 
Issue 3 
Publisher: ACM Press 

Full text available* f£| pdf(284.05 KB) Additional Information: full citation, a bs tra ct , references, citings, index 

terms 

We consider the problem of monitoring an interactive device, such as an implementation 
of a network protocol, in order to check whether its execution is consistent with its 
specification. At rst glance, it appears that a monitor could simply follow the input-output 
trace of the device and check it against the specification. However, if the monitor is able 
to observe inputs and outputs only from a vantage point external to the device— as is 
typically the case— the problem becomes surpris ... 

20 Beyond document similarity: understandin g value-based search and browsin g I I 
<§> technologies 

^ Andreas Paepcke, Hector Garcia-Molina, Gerard Rodriguez-Mula, Junghoo Cho 
March 2000 ACM SIGMOD Record, volume 29 issue 1 
Publisher: ACM Press 

Full text available: |£|pdf(1.29 MB) Additional Information: full citation, abs tr act , c iti n gs, inde x t erms 

In the face of small, one or two word queries, high volumes of diverse documents on the 
Web are overwhelming search and ranking technologies that are based on document 
similarity measures. The increase of multimedia data within documents sharply 
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exacerbates the shortcomings of these approaches. Recently, research prototypes and 
commercial experiments have added techniques that augment similarity-based search and 
ranking. These techniques rely on judgments about the 'value 1 of documents. Jud ... 

Keywords: World-Wide Web, collaborative filtering, hypertext, information filters, 
information retrieval, links, metadata, ranking, relevance, search engines 
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Denial of service (DoS) attack on the Internet has become a pressing problem. In this 
paper, we describe and evaluate route-based distributed packet filtering (DPF), a novel 
approach to distributed DoS (DDoS) attack prevention. We show that DPF achieves 
proactiveness and scalability, and we show that there is an intimate relationship between 
the effectiveness of DPF at mitigating DDoS attack and power-law network topology.The 
salient features of this work are two-fold. First, we show that DPF is ... 
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In this work, we collect and analyze all of the IP and TCP headers of packets seen on a 
network that either violate existing standards or should not appear in modern internets. 
Our goal is to determine the reason that these packets appear on the network and 
evaluate what proportion of such packets could cause actual damage. Thus, we examine 
and divide the unusual packets obtained during our experiments into several categories 
based on their type and possible cause and show the results. 
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Denial of service (DoS) attacks continue to threaten the reliability of networking systems. 
Previous approaches for protecting networks from DoS attacks are reactive in that they 
wait for an attack to be launched before taking appropriate measures to protect the 
network. This leaves the door open for other attacks that use more sophisticated methods 
to mask their traffic. We propose an architecture called Secure Overlay Services (SOS) 
that proactively prevents DoS attacks, geared toward supportin ... 

Keywords: denial of service attacks, network security, overlay networks 
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This paper addresses possible Distributed Denial-of-Service (DDoS) attacks toward the 
wireless Internet including the Wireless Extended Internet, the Wireless Portal Network, 
and the Wireless Ad Hoc network. We propose a conceptual model for defending against 
DDoS attacks on the wireless Internet, which incorporates both cooperative technological 
solutions and economic incentive mechanisms built on usage-based fees. Cost- 
effectiveness is also addressed through an illustrative implementation sche ... 

Keywords: DDoS attack, PBN, wireless ad hoc network, wireless extended internet, 
wireless infrastructure, wireless portal network 
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Today distributed denial of service (DDoS) attacks are causing major problems to conduct 
online business over the Internet. Recently several schemes have been proposed on how 
to prevent some of these attacks, but they suffer from a range of problems, some of them 
being impractical and others not being effective against these attacks. In this paper, we 
propose a Controller-Agent model that would greatly minimize DDoS attacks on Internet. 
With a new packet marking technique and agent design our sc ... 

Keywords: DoS, broad attack signatures, controller-agent model, denial of service, 
packet marking 
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Attackers can render distributed denial-of-service attacks more difficult to defend against 
by bouncing their flooding traffic off of reflectors; that is, by spoofing requests from the 
victim to a large set of Internet servers that will in turn send their combined replies to the 
victim. The resulting dilution of locality in the flooding stream complicates the victim's 
abilities both to isolate the attack traffic in order to block it, and to use traceback 
techniques for locating the source ... 
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It is becoming increasingly common to construct network services using redundant 
resources geographically distributed across the Internet. Content Distribution Networks 
are a prime example. Such systems distribute client requests to an appropriate server 
based on a variety of factors— e.g., server load, network proximity, cache locality-in an 
effort to reduce response time and increase the system capacity under load. This paper 
explores the design space of strategies employed to redirect reque ... 
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The Transportable Applications Environment Plus (TAE Plus) is a NASA-developed user 
interface development environment (UIDE) for the rapid prototyping, evaluation, 
implementation, and management of user interfaces. TAE Plus provides an intuitive What 
You See Is What You Get (WYSIWYG) WorkBench for designing an application's user 
interface. The WorkBench supports the creation and sequencing of displays, including 
real-time, data-driven display objects. Users can define context-sensitive help ... 

Keywords: graphical user interfaces, prototyping, user interface development tools 



12 Intrusion detection: Constructin g attack scenarios through correlation of intrusion 
alerts 



Peng Ning, Yun Cui, Douglas S. Reeves 

November 2002 Proceedings of the 9th ACM conference on Computer and 

communications security CCS '02 
Publisher: ACM Press 

Full text available: f^l pdf(184 18 KB) Additional Information: full citation, abstract, references, cjtings, index 
^ — — t e r ms 

Traditional intrusion detection systems (IDSs) focus on low-level attacks or anomalies, 
and raise alerts independently, though there may be logical connections between them. In 
situations where there are intensive intrusions, not only will actual alerts be mixed with 
false alerts, but the amount of alerts will also become unmanageable. As a result, it is 
difficult for human users or intrusion response systems to understand the alerts and take 
appropriate actions. This paper presents a practical ... 

Keywords: alert correlation, attack scenarios, intrusion detection 
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The current Internet infrastructure has very few built-in protection mechanisms, and is 
therefore vulnerable to attacks and failures. In particular, recent events have illustrated 
the Internet's vulnerability to both denial of service (DoS) attacks and flash crowds in 
which one or more links in the network (or servers at the edge of the network) become 
severely congested. In both DoS attacks and flash crowds the congestion is due neither to 
a single flow, nor to a general increase in traffic, bu ... 
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We present a new approach to IP traceback based on the probabilistic packet marking 
paradigm. Our approach, which we call randomize-and-link, uses large checksum cords to 
"link" message fragments in a way that is highly scalable, for the checksums serve both 
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as associative addresses and data integrity verifiers. The main advantage of these 
checksum cords is that they spread the addresses of possible router messages across a 
spectrum that is too large for the attacker to easily create messages th ... 

Keywords: denial-of-service, packet marking, traceback 
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Conducting cost-benefit analyses of architectural attributes such as security has always 
been difficult, because the benefits are difficult to assess. Specialists usually make 
security decisions, but program managers are left wondering whether their investment in 
security is well spent. This paper summarizes the results of using a cost-benefit analysis 
method called SAEM to compare alternative security designs in a financial and accounting 
information system. The case study presented in this pap ... 
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The design of the IP protocol makes it difficult to reliably identify the originator of an IP 
packet. Even in the absence of any deliberate attempt to disguise a packet's origin, 
widespread packet forwarding techniques such as NAT and encapsulation may obscure the 
packet's true source. Techniques have been developed to determine the source of large 
packet flows, but, to date, no system has been presented to track individual packets in an 
efficient, scalable fashion. We present a hash-based techn ... 

Keywords: IP traceback, computer network management, computer network security, 
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It is widely recognized that distributed denial-of-service (DDoS) attacks can disrupt 
electronic commerce and cause large revenue losses. However, effective defenses 
continue to be mostly unavailable. We describe and evaluate VIPnet, a novel value-added 
network service for protecting e-commerce and other transaction-based sites from DDoS 
attacks. In VIPnet, e-merchants pay Internet Service Providers (ISPs) to carry the 
packets of the e-merchants' best clients (called VIPs) in a privileged class ... 
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This paper provides a quick summary of our technical approach, which has been 
developing since 1991 and was first fielded in MUC-3. First a quick review of what is new 
is provided, then a walkthrough of system components. Perhaps <u>most 
interesting</u> is our analysis, following the walkthrough, of what we learned through 
MUC-6 and of what directions we would take now to break the performance barriers of 
current information extraction technology. 
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